python / python/cpython

PyStructSequence_New() doesn't validate its input type (crashes in os.wait3() and os.wait4() in case of a bad resource.struct_rusage)

未关闭
#75,754 3 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

3.10 3.11 3.9 (EOL) extension-modules type-crash
主要语言
Python
星标
77.2k
派生
36k
PR 合并指标
PR 指标待抓取

描述

BPO 31573
Nosy @vstinner, @serhiy-storchaka, @orenmn, @iritkatriel
PRs
  • python/cpython#3750
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2017-09-25.10:29:33.947>
    labels = ['extension-modules', '3.10', '3.9', 'type-crash', '3.11']
    title = "PyStructSequence_New() doesn't validate its input type (crashes in os.wait3() and os.wait4() in case of a bad resource.struct_rusage)"
    updated_at = <Date 2021-10-18.23:14:00.500>
    user = 'https://github.com/orenmn'
    

    bugs.python.org fields:

    activity = <Date 2021-10-18.23:14:00.500>
    actor = 'iritkatriel'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['Extension Modules']
    creation = <Date 2017-09-25.10:29:33.947>
    creator = 'Oren Milman'
    dependencies = []
    files = []
    hgrepos = []
    issue_num = 31573
    keywords = ['patch']
    message_count = 3.0
    messages = ['302945', '302958', '404243']
    nosy_count = 4.0
    nosy_names = ['vstinner', 'serhiy.storchaka', 'Oren Milman', 'iritkatriel']
    pr_nums = ['3750']
    priority = 'normal'
    resolution = None
    stage = 'patch review'
    status = 'open'
    superseder = None
    type = 'crash'
    url = 'https://bugs.python.org/issue31573'
    versions = ['Python 3.9', 'Python 3.10', 'Python 3.11']
    

    贡献指南

    打开贡献指南

    从这里开始

    1. 先读完整个 Issue,再读项目的贡献指南。
    2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
    3. Fork 仓库,在一个分支上完成修改。
    4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

    调研方向

    首先定位 PyStructSequence_New() 以及 os.wait3() 和 os.wait4() 的入口点,然后检查现有上下文和 PR #3750。完成的标准是,格式错误的 resource.struct_rusage 不再导致这些调用崩溃,并且该行为由适当的回归测试覆盖。

    由索引模型根据 Issue 内容生成。

    评估

    技术栈
    python
    领域
    operating-systems
    Issue 类型
    缺陷
    难度
    4/5
    预计耗时
    3-5 天
    活跃度
    停滞
    描述清晰度
    需要澄清
    新手友好度
    25/100

    把新 issue 发到你的邮箱

    精选适合新手参与的 GitHub issue 摘要。